cbcvebase.

Google Android vulnerabilities

6,770 known vulnerabilities affecting google/android.

Total CVEs
6,770
CISA KEV
13
actively exploited
Public exploits
50
Exploited in wild
24
Severity breakdown
CRITICAL471HIGH2821MEDIUM3190LOW252UNKNOWN36

Vulnerabilities

Page 16 of 339
CVE-2018-9388P3CRITICALCVSS 9.8vKernel2024-12-05
CVE-2018-9388 [CRITICAL] CWE-191 CVE-2018-9388: In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound w In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer underflows. These could lead to escalation of privilege.
nvd
CVE-2020-0245P3HIGHCVSS 8.8v8.0v8.1+4 more2020-09-17
CVE-2020-0245 [HIGH] CWE-787 CVE-2020-0245: In DecodeFrameCombinedMode of combined_decode.cpp, there is a possible out of bounds write due to a In DecodeFrameCombinedMode of combined_decode.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID:
nvd
CVE-2019-1991P3HIGHCVSS 8.8v7.0v7.1.1+4 more2019-02-28
CVE-2019-1991 [HIGH] CWE-787 CVE-2019-1991: In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overfl In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9. Android ID: A-
nvd
CVE-2011-1350P4HIGHCVSS 7.1PoC≤ 2.3.5v1.0+15 more2013-02-05
CVE-2011-1350 [HIGH] CWE-200 CVE-2011-1350: The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive info The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device.
nvd
CVE-2020-0032P3HIGHCVSS 8.8v8.0v8.1+3 more2020-03-10
CVE-2020-0032 [HIGH] CWE-787 CVE-2020-0032: In ih264d_release_display_bufs of ih264d_utils.c, there is a possible out of bounds write due to a h In ih264d_release_display_bufs of ih264d_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-145364230
nvd
CVE-2018-9537P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9537 [HIGH] CWE-787 CVE-2018-9537: In CAacDecoder_DecodeFrame of aacdecode.cpp, there is a possible out-of-bounds write due to a missin In CAacDecoder_DecodeFrame of aacdecode.cpp, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-112891564
nvd
CVE-2018-9521P3HIGHCVSS 8.8v9.02018-11-14
CVE-2018-9521 [HIGH] CWE-787 CVE-2018-9521: In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an inco In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-111874331
nvd
CVE-2017-13228P3HIGHCVSS 8.8v6.0v6.0.1+5 more2018-02-12
CVE-2017-13228 [HIGH] CWE-787 CVE-2017-13228: In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount bei In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an unsigned character. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A
nvd
CVE-2019-1989P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-1989 [HIGH] CWE-787 CVE-2019-1989: In ih264d_fmt_conv_420sp_to_420p of ih264d_format_conv.c, there is a possible out of bounds write du In ih264d_fmt_conv_420sp_to_420p of ih264d_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 And
nvd
CVE-2019-1990P3HIGHCVSS 8.8v7.0v7.1.1+5 more2019-06-19
CVE-2019-1990 [HIGH] CWE-787 CVE-2019-1990: In ihevcd_fmt_conv_420sp_to_420p of ihevcd_fmt_conv.c, there is a possible out of bounds write due t In ihevcd_fmt_conv_420sp_to_420p of ihevcd_fmt_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Androi
nvd
CVE-2019-2185P3HIGHCVSS 8.8v7.1.1v7.1.2+5 more2019-10-11
CVE-2019-2185 [HIGH] CWE-787 CVE-2019-2185: In VlcDequantH263IntraBlock_SH of vlc_dequant.cpp, there is a possible out of bounds write due to a In VlcDequantH263IntraBlock_SH of vlc_dequant.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android-10And
nvd
CVE-2019-2184P3HIGHCVSS 8.8v7.1.1v7.1.2+4 more2019-10-11
CVE-2019-2184 [HIGH] CWE-787 CVE-2019-2184: In PV_DecodePredictedIntraDC of dec_pred_intra_dc.cpp, there is a possible out of bounds write due t In PV_DecodePredictedIntraDC of dec_pred_intra_dc.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9Android I
nvd
CVE-2019-2186P3HIGHCVSS 8.8v7.1.1v7.1.2+5 more2019-10-11
CVE-2019-2186 [HIGH] CWE-787 CVE-2019-2186: In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing boun In GetMBheader of combined_decode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-
nvd
CVE-2019-2093P3HIGHCVSS 8.8v9.02019-06-07
CVE-2019-2093 [HIGH] CWE-787 CVE-2019-2093: In huff_dec_1D of nlc_dec.cpp, there is a possible out of bounds write due to a missing bounds check In huff_dec_1D of nlc_dec.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-9. Android ID: A-119292397.
nvd
CVE-2019-2177P3HIGHCVSS 8.8v7.1.1v7.1.2+4 more2019-09-05
CVE-2019-2177 [HIGH] CWE-275 CVE-2019-2177: In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible devic In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible device type confusion due to a permissions bypass. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
CVE-2020-0489P3HIGHCVSS 8.8v11.0vAndroid-112020-12-15
CVE-2020-0489 [HIGH] CWE-787 CVE-2020-0489: In Parse_data of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. In Parse_data of eas_mdls.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151096540
nvd
CVE-2021-0918P3HIGHCVSS 8.8v12.0vAndroid-122021-12-15
CVE-2021-0918 [HIGH] CWE-787 CVE-2021-0918: In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to a missing In gatt_process_notification of gatt_cl.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197536150
nvd
CVE-2022-20345P3HIGHCVSS 8.8v12.0v12.1+1 more2022-08-10
CVE-2022-20345 [HIGH] CWE-787 CVE-2022-20345: In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bo In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-230494481
nvd
CVE-2024-20009P3HIGHCVSS 8.8v12.0v13.0+1 more2024-02-05
CVE-2024-20009 [HIGH] CWE-787 CVE-2024-20009: In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This co In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS08441150; Issue ID: ALPS08441150.
nvd
CVE-2018-9470P3HIGHCVSS 8.8v7.0v7.1.1+9 more2024-11-20
CVE-2018-9470 [HIGH] CWE-787 CVE-2018-9470: In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect b In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.
nvd
Google Android vulnerabilities | cvebase